McAfee Database Security 6Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-06-070x00 Îó²î¸ÅÊö
McAfee Êý¾Ý¿âÇå¾²²úÆ·Äܹ»ÊµÊ±±£»£»£»¤Òªº¦ÓªÒµµÄÊý¾Ý¿â£¬£¬£¬£¬£¬×èÖ¹ÆäÔâÊÜÍⲿ¡¢ÄÚ²¿ºÍÊý¾Ý¿âÄÚ²¿µÄÖÖÖÖ¹¥»÷¡£¡£¡£¡£
2021Äê06ÔÂ01ÈÕ£¬£¬£¬£¬£¬McAfeeÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´ÁËDatabase SecurityÖеÄ5¸öÇå¾²Îó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÕâЩÎó²îδÊÚȨ»á¼û¡¢»ñÈ¡Ãô¸ÐÐÅÏ¢»ò¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£
0x01 Îó²îÏêÇé
±¾´ÎÐÞ¸´µÄ5¸öÎó²îÖУ¬£¬£¬£¬£¬CVE-2021-23894ºÍCVE-2021-23895ÊÇMcAfee Database Security £¨DBSec£©Öеķ´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬Î´¾ÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâ¹¹½¨µÄJavaÐòÁл¯¹¤¾ßµ½DBSecЧÀÍÆ÷À´´¥·¢´ËÎó²î£¬£¬£¬£¬£¬²¢Í¨¹ýÔÚDBSecЧÀÍÆ÷ÉϽ¨Éè¾ßÓÐÖÎÀíԱȨÏ޵ķ´ÏòshellÀ´¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£
CVE-2021-31830ÊÇDBSecÖеÄXSSÎó²î£¬£¬£¬£¬£¬ÓµÓÐÖÎÀíȨÏ޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ýÔÚÉèÖÃÒª¼à¿ØµÄÊý¾Ý¿âÃû³ÆÊ±Ç¶ÈëJavaScript´úÂ룬£¬£¬£¬£¬µ±ÈκÎÊÚȨÓû§µÇ¼µ½DBSec½çÃæ²¢·¿ª¸ÃÊý¾Ý¿âµÄÊôÐÔÉèÖÃÒ³ÃæÊ±£¬£¬£¬£¬£¬½«´¥·¢¶ñÒâ´úÂ룬£¬£¬£¬£¬µ«Ê¹ÓôËÎó²îÐèÒªÓû§½»»¥¡£¡£¡£¡£
CVE-2021-31831ÊÇDBSecÖÐÒÑɾ³ý¾ç±¾µÄ²»×¼È·»á¼ûÎó²î£¬£¬£¬£¬£¬ÕâЩ¾ç±¾±»±£´æÏÂÀ´£¬£¬£¬£¬£¬ÒÔ±ãÔÚδÀ´ÐèÒªÆÊÎöÍùÊÂÎñʱʹÓᣡ£¡£¡£µ«¾ÓÉÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýREST API»ñµÃ¶ÔÖÎÀí¿ØÖÆÌ¨ÖÐÒѱê¼ÇΪɾ³ý»òÓâÆÚµÄÊðÃûSQL¾ç±¾µÄ»á¼û£¬£¬£¬£¬£¬µ«Ê¹ÓôËÎó²îÐèÒªÓû§½»»¥¡£¡£¡£¡£
CVE-2021-23896ÊÇDBSecÖÎÀíÔ±½çÃæÖеÄÃô¸ÐÐÅÏ¢Ã÷ÎÄ´«ÊäÎó²î£¬£¬£¬£¬£¬ÓµÓÐÖÎÀíȨÏ޵Ĺ¥»÷Õß¿ÉÒÔʹÓôËÎó²îÉó²éMcAfee Insights ServerµÄδ¼ÓÃÜÃÜÂ룬£¬£¬£¬£¬µ«Ê¹ÓôËÎó²îÐèÒªÓû§½»»¥¡£¡£¡£¡£
CVE-ID | ÀàÐÍ | CVSSv3ÆÀ·Ö | Ó°Ïì¹æÄ£ |
CVE-2021-23894 | ·´ÐòÁл¯ | 9.6 | < 4.8.2 |
CVE-2021-23895 | ·´ÐòÁл¯ | 9.0 | |
CVE-2021-23896 | ÐÅϢй¶ | 3.2 | |
CVE-2021-31830 | XSS | 5.9 | |
CVE-2021-31831 | »á¼û¿ØÖƹýʧ | 4.9 |
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚMcAfeeÒѾÔÚDBSec 4.8.2ÖÐÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶¸üУº
ÏÂÔØÅþÁ¬£º
https://www.mcafee.com/enterprise/en-us/downloads.html
0x03 ²Î¿¼Á´½Ó
https://kc.mcafee.com/corporate/index?page=content&id=SB10359#Remediation
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23894
https://nvd.nist.gov/vuln/detail/CVE-2021-23894
0x04 ʱ¼äÏß
2021-06-01 McAfeeÐû²¼Ç徲ͨ¸æ
2021-06-02 McAfee¸üÐÂÇ徲ͨ¸æ
2021-06-07 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/